Show filters
119 Total Results
Displaying 111-119 of 119
Sort by:
Attacker Value
Unknown

CVE-2002-0986

Disclosure Date: September 24, 2002 (last updated February 22, 2025)
The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."
0
Attacker Value
Unknown

CVE-2002-0484

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
0
Attacker Value
Unknown

CVE-2002-0253

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.
0
Attacker Value
Unknown

CVE-2002-0229

Disclosure Date: May 16, 2002 (last updated February 22, 2025)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.
0
Attacker Value
Unknown

CVE-2002-0121

Disclosure Date: March 25, 2002 (last updated February 22, 2025)
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
0
Attacker Value
Unknown

CVE-2001-1247

Disclosure Date: December 06, 2001 (last updated February 22, 2025)
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.
0
Attacker Value
Unknown

CVE-2001-0320

Disclosure Date: May 03, 2001 (last updated February 22, 2025)
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
0
Attacker Value
Unknown

CVE-2001-0108

Disclosure Date: March 12, 2001 (last updated February 22, 2025)
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
0
Attacker Value
Unknown

CVE-2001-1385

Disclosure Date: January 12, 2001 (last updated February 22, 2025)
The Apache module for PHP 4.0.0 through PHP 4.0.4, when disabled with the 'engine = off' option for a virtual host, may disable PHP for other virtual hosts, which could cause Apache to serve the source code of PHP scripts.
0